CVE-2010-3425
Summary
| CVE | CVE-2010-3425 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-09-16 22:00:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cross-site scripting (XSS) vulnerability in UserControls/Popups/frmHelp.aspx in SmarterStats 5.3, 5.3.3819, and possibly other 5.3 versions, allows remote attackers to inject arbitrary web script or HTML via the url parameter. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Smartertools | Smarterstats | 5.3 | All | All | All |
| Application | Smartertools | Smarterstats | 5.3.3819 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.osvdb.org/67895 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Exploit |
| SmarterStats "url" Cross-Site Scripting Vulnerability - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| XSS.Cx Blog | af854a3a-2127-422b-91ae-364da2661108 | cloudscan.blogspot.com | Exploit |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| smartertools | 2010-10-05 | smartertools | SmarterTools has released SmarterStats 5.4.3925, which addresses this security vulnerability as well as the latest ASP.NET vulnerabilities announced by Microsoft. It is recommended to upgrade to the latest version as soon as possible. Download the latest release at http://www.smartertools.com/smarterstats/web-analytics-seo-software-download.aspx. Release notes are available at http://www.smartertools.com/smarterstats/releasenotes/v5.aspx. |
There are currently no legacy QID mappings associated with this CVE.